Microsoft Defender flags legitimate Google search links as malicious

3 hours ago 7

Microsoft Defender

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly flag legitimate Google search links as malicious.

The company first acknowledged the incident (tracked under MO1465962) at 10:30 AM UTC and says affected users are seeing "Opening this website might not be safe" warnings when trying to open the blocked hyperlinks.

According to a service alert seen by BleepingComputer, the issue is caused by an inaccurate security classification, and copying the links and pasting them directly into a browser will not bypass the warning.

Microsoft also warned IT administrators that they may see alerts in the Microsoft Sentinel security information and event management (SIEM) solution and the Defender portal regarding this ongoing incident.

"Microsoft Defender for Office 365 Safe Links may block the opening of Google search links (URLs), identifying them as malicious. In addition, admins may receive related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel as a result of these detections," Microsoft said.

"We've determined that an inaccurate security classification is causing legitimate Google search URLs to be incorrectly identified as malicious, resulting in Microsoft Defender for Office 365 Safe Links blocking access to affected links. We're working to correct the misclassification to remediate impact."

Safe Links blocks malicious links used in phishing and other attacks by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs in email messages, Teams, and Office 365 apps in organizations with a Defender for Office 365 license.

While Microsoft has yet to disclose which regions are impacted or how many customers are affected, it has classified it as an advisory, which is typically used to describe service issues involving limited scope or impact.

Microsoft has addressed similar false positive issues over the last several years that resulted in links and messages being incorrectly tagged as malicious or quarantined.

For instance, last year, an Exchange Online bug caused a machine learning model to mistakenly flag emails from Gmail accounts as spam, while another one caused anti-spam systems to quarantine some users' legitimate emails.

More recently, in February, an Exchange Online issue prevented users from sending or receiving emails and flagged legitimate messages as phishing, quarantining them.

Microsoft is also working to address a massive, widespread Microsoft 365 outage causing authentication issues, service delays and failures, connection problems, and other issues.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Read Entire Article